30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

1.19 TC-10-CorruptImage<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Test Case TC-10-CorruptImage (FTK Imager 2.9.0.1385)<br />

Test &<br />

Case<br />

Summary:<br />

Try verifying a corrupted image<br />

Notes: The image <strong>of</strong> FAT32 partition.<br />

Assertion: AFR-03 The tool operates in an execution environment<br />

AIC-06 If the image file integrity check is selected, the tool shall report<br />

to the user the image file has not been changed if the image file<br />

has not been changed.<br />

AIC-07 If the image file integrity check is selected, the tool shall report<br />

to the user the image file has been changed if the image file<br />

has been changed.<br />

AIC-08 If the image file integrity check is selected, the tool shall report<br />

to the user the image file has been changed and the involved<br />

location if the image file has been changed.<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Setup:<br />

Log<br />

highlights:<br />

consistent with the log file if the log file function is supported<br />

Drive Model: ST380811 AS (80GB)<br />

Serial Number: 6PS2CA4Z<br />

Sector count: 156,296,385<br />

Write blocker: N/A<br />

Source image hashes<br />

MD5 checksum: 2c22fded78dc8ccc2c935944883a2e1b<br />

SHA1 checksum: 10eaa99a609cd8d215c9dc5a68f46e2e0d5c68c5<br />

Total sectors: 2104452 (1027MB)<br />

Address: Offset 35df5f70h Column 8 change byte from 43 to 42<br />

/dev/sda: current max LBA: 156,296,385<br />

/dev/sda: native max LBA: 156,296,385<br />

/dev/sda: physical max LBA: 156,296,385<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Device Start End #Sectors File System<br />

/dev/sda1 63 41945714 41945652 HPFS/NTFS<br />

/dev/sda2 4192965 156296384 152103420 Extended<br />

/dev/sda5<br />

/dev/sda6<br />

4193028<br />

6297543<br />

6297479<br />

10490444<br />

2104452<br />

4192902<br />

FAT32<br />

FAT16<br />

/dev/sda7 10490508 12594959 1052226 Ext2<br />

/dev/sda8 12595023 14699474 2104452 Ext3<br />

/dev/sda9 14699538 18892439 4192902 HPFS/NTFS<br />

/dev/sda10 18892503 19149479 256977 Swap<br />

unallocated 19149480 156296384 137146905 Empty<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Notes: Acquire FAT32 partition only (sector first from 4193028 to<br />

6297479. total: 2104452).<br />

186

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!